Impact
A heap‑based buffer overflow in the Windows Storage Port Driver can be triggered by an attacker who has local access to the system. The flaw arises when the driver mishandles heap allocations, allowing unintended memory overwrite and the execution of code with higher privilege levels. This escalation permits unauthorized configuration changes, data theft, or the installation of additional malware.
Affected Systems
The vulnerability impacts Microsoft Windows 11 versions 24H2, 25H2 and 26H1, as well as Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity local privilege escalation. While the EPSS score is < 1% and the flaw is not listed in CISA KEV, the lack of widespread exploitation data does not reduce the risk to environments where local users can write to the driver. The attack vector is local; an authorized or compromised local user must trigger the overflow to gain elevated administrative rights. No additional conditions are noted beyond local access.
OpenCVE Enrichment